CVE-2026-23492 | Pimcore up to 11.5.13/12.3.0 Admin Search Find API sql injection (GHSA-qvr7-7g55-69xj / EUVD-2026-2449)
A vulnerability was found in Pimcore up to 11.5.13/12.3.0. It has been declared as critical. This impacts an unknown function of the component Admin Search Find API. The manipulation results in sql injection.
This vulnerability is known as CVE-2026-23492. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.